URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469854
URL: http://154.205.128.91/zd/arm7
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:28:04 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:29:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 4 minutes Bad (down since 2025-04-16 14:33:09 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf bfc80a1e1c6d8791d367551ff225b0a6eef582552fa42759dce02120617d084en/aMirai
2025-04-12n/aelf f904c435422fc94f930c2d89741b8d9b4867ebedc40f61c51d98f016cd1c503en/aMirai
2025-04-02n/aelf 44ff52b0edd0d1cf3dbba6c6b0ea298c39673b7011726452a70698fd07866568n/aMirai
2025-03-25n/aelf 188317f726c10aa4bbe48c88c25b0f0ee68e0001d600ab396fd1e89c8ac63ca4n/aMirai
2025-03-24n/aelf 6826078f8cbd788468eadcde4030cfef90c6cc7f0096d56a75b7de0ec4b8f357n/aMirai
2025-03-17n/aelf fccdde510e6dce01530d73df68fb3d976853905f5f1b5226d103b557ccebd089Virustotal results 34.38%Mirai
2025-03-14n/aelf f54e87f150445843b2a5ea873e5d0433cdaac38333d2b8153600beb00807aab0n/aMirai
2025-03-11n/aelf 06c9818aec332816ab7c81e1919185427634294c019221c60568144e7d537113Virustotal results 17.46%Mirai
2025-03-09n/aelf d5d996be2dbfd0337e360e2eed1879c56be8d4d9cebf47026c997f892b34aa4fn/aMirai
2025-03-06n/aelf 70dc018a5b087b4f709460d3c580afece781405609cf8b8b69146a66a3f45e01n/aMirai